← Vulnerability feed

Vulnerability record · CVE-2024-2054 · published 21 March 2024

CVE-2024-2054: Artica Proxy unauthenticated PHP object deserialization leads to code execution

AArticatech · Artica Proxy

Artica-Proxy's administrative web application deserializes arbitrary PHP objects supplied by unauthenticated users, which then allows code execution as the www-data user. Because the flaw is reachable without credentials and requires no user interaction, it exposes the proxy's web interface to remote compromise. The record does not list affected versions or fixed releases.

9.8 CVSS 3.1 Critical EPSS 81% · top 0.4% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a 9.8 CVSS score, public exploit references and a 99.6th percentile EPSS probability make this an urgent exposure despite no KEV listing.

What it is

Artica-Proxy's administrative web application deserializes arbitrary PHP objects supplied by unauthenticated users, which then allows code execution as the www-data user. Because the flaw is reachable without credentials and requires no user interaction, it exposes the proxy's web interface to remote compromise. The record does not list affected versions or fixed releases.

Impact

An attacker can run arbitrary code as the www-data user on the Artica-Proxy host, giving full control of the web application context and a foothold for further compromise. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network through the Artica-Proxy administrative web application; the CVSS vector is AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. The description confirms the malicious PHP objects are supplied by unauthenticated users.

Exploitation

CISA KEV does not list this CVE, but public exploit references are present (Exploit-tagged Full Disclosure and KoreLogic advisory), and EPSS is very high at 0.8126 (99.6th percentile), indicating likely active exploitation attempts.

What to do

  • Apply the vendor fix for Artica-Proxy as soon as a patched release is available; the record does not name a fixed version, so confirm with the vendor.
  • Restrict network access to the Artica-Proxy administrative web interface to trusted management networks or VPN only.
  • If patching is not immediately possible, take the administrative interface offline or place it behind an authenticating reverse proxy.
  • Run the Artica-Proxy service under a least-privilege account and review file permissions for the www-data user.
  • Monitor vendor and KoreLogic advisories for updated guidance and fixed versions.

Detection

  • Inspect web server and Artica-Proxy logs for POST requests to administrative endpoints containing serialized PHP object payloads (for example O: or a: patterns) from unauthenticated clients.
  • Alert on unexpected child processes or command execution spawned by the www-data user or the Artica-Proxy web process.
  • Monitor for outbound connections or file writes originating from the Artica-Proxy host that are inconsistent with normal proxy behavior.
  • Review access logs for scanning or exploitation attempts against the administrative interface from untrusted source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-2054 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-2055Articatech artica proxy authentication bypass via alternate path vulnerabilityThe "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does …EPSS 0.93%9.8CVE-2024-2056Articatech artica proxy authentication bypass via alternate path vulnerabilityServices that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailo…EPSS 17%9.8CVE-2021-41739Articatech artica proxy os command injection vulnerabilityA OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param…EPSS 2.6%9.8CVE-2020-13159Articatech artica proxy os command injection vulnerabilityArtica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Al…EPSS 9.3%9.0CVE-2017-17055Articatech artica proxy os command injection vulnerabilityArtica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack invol…EPSS 8.7%7.5CVE-2024-2053Articatech artica proxy relative path traversal vulnerabilityThe Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code…EPSS 45%7.5CVE-2020-15052Articatech artica proxy sql injection vulnerabilityAn issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields.EPSS 2.2%7.5CVE-2020-13158Artica Proxy directory traversal in fw.progrss.details.php popup parameterArtica Proxy Community Edition before 4.30.000000 is vulnerable to directory traversal through the popup parameter of fw.progrss.details.php. An unau…EPSS 54%analysed

Source: NIST National Vulnerability Database (record CVE-2024-2054), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.